DataBreachLegalTeam.com
MonitoringWashington AG filing · April 16, 2026

Providence Health Gorilla Data Breach Exposes Patient Records

Providence and Health Gorilla reported a data breach to Washington authorities on April 16, 2026, compromising highly sensitive patient information. This incident exposed core medical and personal data, including Social Security Numbers, for an unknown number of individuals. Those affected now face increased risks of medical identity theft and various forms of fraud due to potential security vulnerabilities at these healthcare entities.

Received a Providence (Health Gorilla) notification letter? Find out in minutes if you qualify for compensation.

Free case review
State
Washington
Reported
April 16, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates

On April 16, 2026, Providence, along with its associated platform Health Gorilla, formally reported a data security incident to the Washington Attorney General. This breach highlights growing vulnerabilities within the vast healthcare data networks that manage critical patient information.

The compromised information includes deeply personal and immutable data categories. Specifically, individuals may have had their Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates exposed. Unlike a credit card that can be easily replaced, this type of data, especially medical history and Social Security Numbers, cannot be changed and carries long-term risks.

Exposure of such sensitive data can lead to serious consequences, including medical identity theft, where unauthorized individuals might receive care under your name, falsifying your medical records and potentially introducing life-threatening errors into future treatments. Additionally, compromised identifying details can facilitate insurance fraud, tax fraud, and targeted phishing scams.

As major healthcare providers and data handlers, Providence and Health Gorilla are legally obligated under HIPAA and Washington state regulations to implement robust safeguards to protect patient data. The occurrence of a breach of this magnitude suggests potential failures in upholding these mandated security standards, raising questions about institutional responsibility and accountability.

If you received a data breach notification letter from Providence or Health Gorilla, it confirms that your confidential records were compromised. Receiving this notice provides you with legal standing to explore potential claims. Our team is actively investigating this data breach, and we offer free case reviews on a contingency basis, meaning there are no out-of-pocket costs to you unless we successfully recover compensation on your behalf.

Received the Providence (Health Gorilla) notification letter? The Providence (Health Gorilla) case file tracks this filing.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Washington Attorney General filing

Related data breach cases